Infosecurity News

Human Error Fuels Industrial APT Attacks, Kaspersky Reports
OT network admins grant access to employees or contractors without sufficient security measures

DogeRAT Malware Impersonates BFSI, Entertainment, E-commerce Apps
Discovered by CloudSEK, the malicious campaign relies on open source Android malware

Ransomware Gangs Adopting Business-like Practices to Boost Profits
Cyber-criminal gangs are mirroring the practices of legitimate businesses to drive efficiencies and increase profits

Dark Web Data Leak Exposes RaidForums Members
Cybercrime site was taken down by the authorities in 2022

Retailer Database Error Leaks Over One Million Customer Records
SimpleTire snafu has now been remediated

Nine Million MCNA Dental Customers Hit by Breach
LockBit ransomware group has claimed responsibility

New Mirai Variant Campaigns are Targeting IoT Devices
Unit 42 researchers observed that a wave of malicious campaigns, all deployed by the same threat actor, have been using IZ1H9 since November 2021

New Russian-Linked Malware Poses “Immediate Threat” to Energy Grids
Researchers say the specialized OT malware has similarities with Industroyer, which was used to take down power in Kiev, Ukraine, in 2016

Romania’s Safetech Leans into UK Cybersecurity Market
The cyber innovator sees the UK is an ideal location to realize its global ambitions as it opens a SOC at the Plexal Innovation Hub

Advanced Phishing Attacks Surge 356% in 2022
Perception Point said the increase is due to the adoption of new cloud collaboration apps

Expo Framework API Flaw Reveals User Data in Online Services
The vulnerability was discovered by Salt Security and has a CVSS score of 9.6

NCSC Warns Against Chinese Cyber Attacks on Critical Infrastructure
The threat actors used sophisticated tactics to evade detection during their malicious activities

SMBs Targeted by State-Aligned Actors for Financial Theft and Supply Chain Attacks
Proofpoint researchers have found that small and medium-sized businesses are increasingly being targeted by APT actors globally

AI Used to Create Malware, WithSecure Observes
The cybersecurity firm confirms that it has observed AI being used to generate malware

Lazarus Group Targeting Microsoft Web Servers to Launch Espionage Malware
Researchers detail the DLL side-loading technique used to deploy malware that facilitates credential theft and lateral movement

US Sanctions North Korean Entities Training Expat IT Workers in Russia, China and Laos
Illicit North Korean IT workers send the money they made from abroad to fund Kim’s regime, US Treasury Department said

Private Sector Cybersecurity Task Force Called for to Defend Democracies
Jessica Berlin, an independent consultant, calls for private sector task force to defend democracies

Diversity advocate and renowned practitioner, Becky Pinkard, to be Inaugurated into Infosecurity Europe's Hall of Fame
Becky will be officially inducted into the Hall of Fame during Infosecurity Europe 2023

Backup Repositories Targeted in 93% of Ransomware Attacks
Organizations now acknowledge that having clean and recoverable backups is a critical element of a good business continuity plan

50% of UK CEOs See Cyber as a Bigger Business Risk than the Economy
The survey also revealed that UK CEOs have a low level of understanding of cyber risks



